Dangling Pointer Vulnerability in PDFio Product by Michael Sweet
CVE-2026-77220
7.1HIGH
What is CVE-2026-77220?
PDFio prior to version 1.6.5 is vulnerable to a dangling pointer flaw that can significantly compromise document integrity. The issue arises from the dictionary string-formatting function that incorrectly stores a pointer to a stack-local buffer without copying the actual string value. In multi-threaded scenarios or pooled request environments, this vulnerability allows attackers or concurrent users to exploit the stack memory reuse. As a result, one caller’s dictionary string values can be silently overridden by the data of another caller, leading to cross-tenant document content corruption. It is crucial for users to update to version 1.6.5 or later to safeguard against this risk.
Affected Version(s)
pdfio 0
